Indicator Lookup
Paste an indicator and get it straight to the services that can answer questions about it — no retyping, no hunting for the right search box. The type is detected automatically and defanged input is understood.
Before you click
Querying a third party is itself a disclosure. Looking up an attacker-controlled domain or uploading a sample tells that service — and in some cases the wider world — that someone is investigating. Adversaries do monitor public sandbox submissions and certificate logs for their own infrastructure. During a live incident, a careless lookup can tip off the intruder and trigger destruction of evidence.
Treat file hashes as safe to look up and URLs and domains as a judgement call. If in doubt, use passive sources first — certificate transparency, WHOIS history, passive DNS — and leave the active scanners until containment is complete. Never paste customer data, credentials or internal hostnames into a public service.
This page runs entirely in your browser. The indicator you type is never sent to Threat Sentinel, is not logged and is not stored — it only leaves your machine when you deliberately click one of the links, and then it goes to that service alone.